Pinboard.in service limited - FBI raided hosting company and pulled equpiment
status.pinboard.in
status.pinboard.in
Keep it up Pinboard!
+1 Maciej. I am glad I paid for an account.
Not to mention it's dead-simple to use.
See http://status.pinboard.in/ or @pinboard on Twitter for updates.
Maybe a temporary loss of functionality earned you a few users above the daily average.
They do officially have policies and programs designed to befriend local businesses in the area of a field office. They just want to catch the bad guys and not mess with the innocent. They want people to like them and trust them. They count on the cooperation of businesses, especially hosting and access providers. There are civilized processes for everyone to get what they want.
There are the cases of people trying to get information who are not actually law enforcement, and that is one of the many reasons you must ask for a subpoena... To protect yourself and your customers privacy. The FBI can get one in a very short time.
Where this all goes bad is when you do not respond to subpoenas for subscriber information, when you don't hand over the disks, etc. If you do not comply, then what alternative does the FBI have but to come and get it?
My guess?... The host didn't play nice with the FBI.
This happens more often than you might think.
Off site backups, executed masterfully here saves the day.
There are a few services that I run on servers in separate countries. Failure of reasonable rule of law within a single country is a failure mode we consider.
A 2008 post by a libertarian law professor (http://volokh.com/posts/1209706276.shtml) argued that the Takings Clause (which requires compensation if e.g. land is taken to build a highway or military base) should also require the government to pay compensation to innocent third parties inconvenienced or harmed during the course of a criminal investigation. But, that post noted that no high courts had actually held that, and at least one appeals court had just held to the contrary.
This is in the normal case, at least; things would probably be different if it were deemed to be some sort of overt act, e.g. if a police chief orders a raid designed to intentionally damage an innocent third party's interests (and you have evidence to show that).
What would happen if the police shut down entire city blocks because one business in that block was breaking the law?
All those costs would dwarf the cost of building a fault tolerant architecture from the start. Having a distributed architecture protects you from random law enforcement activities, power/communications outages, or even just glitchy hardware. Not only that, but it offers the advantage of built-in scalability should your business exceed your current capacity. Unless you have massive amounts of legacy infrastructure, data, and code which makes it cost prohibitive to migrate, it's really cheap these days to have a proper distributed architecture from the start.
Apparently the FBI took three racks. If those are whole racks, it seems excessive. https://twitter.com/#!/Pinboard/status/83256217174147072
But another issue is that Digital One told Pinboard this was due to bad router firmware -- how do you confuse a software issue and an FBI raid? https://twitter.com/#!/Pinboard/status/83257679023325186
1. suspect that someone had walked away with 3 racks, or
2. guess that some network hardware had gone bad?
Usually it's a horse, but sometimes it's a zebra.In the United States we might start considering computer equipment as private spaces, not unlike our residents and vehicles. With so much of our lives increasingly digital in nature, it's not that screwy of an idea that law enforcement should require a search warrant for computer equipment and storage media.
> In the United States we might start considering computer
> equipment as private spaces, not unlike our residents and
> vehicles. With so much of our lives increasingly digital
> in nature, it's not that screwy of an idea that law
> enforcement should require a search warrant for computer
> equipment and storage media.
That's not at all the issue. The 4th amendment has been extended to digital media:http://www.cybercrime.gov/ssmanual/index.html
I'd be willing to bet my house that the law enforcement had a search warrant to take the data in question.
The problem is that the government's strategy -- grab the hardware -- doesn't work well when the hard drive is a virtual disk that sits on a server with a ton of other virtual disks.
Ultimately though, I think this isn't a question that can be solved by technical means. The solution is going to come when law enforcement can come up with a way of "confiscating" the virtual disks that doesn't open the door for claims of tampering & evidence planting.
> The problem is that the government's strategy -- grab the hardware -- doesn't work well when the hard drive is a virtual disk that sits on a server with a ton of other virtual disks.
A fine point. I assert that the government should, then, have to receive a search warrant for each individual's data on the specific piece of hardware. Consider the search of an apartment complex: getting a warrant for one residence of the building does not grant search rights for every other residence. My contention is that physical disks with many virtual disks should be treated as multiple tenant property, as indeed it is.
Thank you for the comment and the citation.
I would, however, imagine that the police would need a warrant to search any other virtual disk.
But the seizure of those disks raises an interesting legal question. Any lawyers know the answer?
Going back to your hypothetical, if the resident of 3A were stuffing materials of interest into the crawlspace between their ceiling the the floor of 4B and said crawlspace could only be accessed through the floor of 4B, the interested authorities would need either the express permission of the residents of 4B for entry into their residence or a warrant for search. _That_, I assert, is a similar situation akin to the topic under discussion.
But the government is going to claim that its "right" to get at the evidence is stronger than the property rights of the other co-resident users.
Consider: the 4th Amendment isn't in effect when you're within 100 miles (?) of the border; the chance of smuggling, etc., is greater there, so the need to detain and search people in that zone outweighs our rights. Or, consider a case in which my buddy borrows my car, and is seen driving through an unsavory neighborhood, is stopped, and found with a big sum of cash. This gives them the "right" to confiscate my car because it was involved in drug trafficking, even though no crime has been committed, and I wasn't involved in any case.
However, that particular issue is not germane to the case in point, which appears to involve the FBI rather than immigration/border patrol.
Your post is high on hyperbole and fear but low on content.
Just because the government has the legitimate right to conduct warrantless searches under conditions {x,y,z} doesn't mean they have rights to conduct warrantless searches under any other condition, or under all conditions.
The feds could do plenty, but won't. The legal system is slow to react, and the feds likely fear that just taking virtual disks would lead to evidentiary issues at trial.
Hosting providers might be able to provision in a way that the servers hosting evil.site could be taken by the feds but backups existed of the other sites, but it would be an extremely hard -- if not impossible -- task.
In the end, cloud computing doesn't change the rules of safely deploying your site to the world -- if you care about uptime & your data, your site must be running on at least two different hosts.
Honest question: why are physical hard disks more valid as evidence than virtual ones? Aren't they equally easy to tamper with?
But the police have a well designed chain of custody system to at least reduce the possibility of tampering. Not everybody in the office can tamper with evidence behind lock and key with seals -- of course it still happens, but the goal is to reduce the possibility.
This falls apart when the evidence in question is data that can be copied, altered, etc.
And of course we can likely come up with clever cryptographic answers to this problem, but in the end, it's far easier and a more understood procedure for the police just to grab hardware and seal it up.
Do you want to explain to 12 randomly selected people how virtual disks work, and the cryptographic algorithms you used to ensure that the data you're showing them is identical to the data the defendant had on their system? Could you explain it so well that a reasonably skilled defense attorney couldn't confuse them enough to produce reasonable doubt?
...or is the answer that the law has no adequate treatment of abstract evidence?
Everything.
Moving rack after rack into waiting trucks makes for excellent TV.
Somewhere in the FBI, right now, is a man or woman powerful enough and ignorant enough to order such a seizure. It's pretty much inevitable.
[1] The original link is broken, but I discussed it at the time here: http://clubtroppo.com.au/2009/04/05/on-a-risk-i-had-not-cons...
Would the FBI turn up and say "Where's the 100 servers for customer X", then seize up to 100 different physical servers, depending on the distribution? Or even 100 racks worth of physical servers...
I can imagine in an Amazone datacenter they would be able to point to the exact server they're looking for.
Mentioning the specifics of Amazon further, what about if your account for the highly illegal operation was using/paying for EBS/S3/SimpleDB/RDS/SQS/SNS/SES (or all at the same time). Any could contain forensic evidence of a crime as they hold data in some sense. EBS especially is likely to run on some kind of SAN; would they have to crack open the racks and take out individual drives? would they have to take whole arrays of discs because of RAID-esque striping?
It's like a LEO denial of service (both on amazon and the forensic analysis). Pragmatically, they might trust amazon enough to consolidate/quarantine the data into the smallest surface area first.
i.e., I'm hosted on the same server as Joe, who the FBI are investigating. They seize the equipment we share. During the course of their investigation, they naturally also examine my data.
Do I then have a viable lawsuit or claim towards unlawful search & seizure, or invasion of privacy? Or, if I happened to also have illegal content on the same system, would they be able to use the evidence they encountered there in a case against me?
So, all things being equal, the FBI is supposed to take pains not to even look at the data of people not named on the warrant (automated processes have been exempted from this, IIRC, as they aren't actual people), even though your data is housed on the save server as the person(s) named on the warrant. And if they did by chance see something they weren't supposed to, it wouldn't be admissible in court (in a case against you - they might be able to use it against someone else).
IANAL, I just took a couple of law courses in college.
That's an interesting point. So, if I'm running a hosting company, and they come across data from one of my customers...?
Also, putting aside for a moment IT best practices and all that, they potentially are crippling my business by seizing machines which I share with someone else. Is there any recourse for that?
The WP article below specifically talks about communications, but the skeptic in me doubts there is much change between one form of data and another in a highly bureaucratic environment such as the NSA.
http://en.wikipedia.org/wiki/Thomas_Andrews_Drake
http://www.washingtonpost.com/wp-dyn/content/article/2010/07...
I wonder why the FBI is raiding all these servers. Another comment mentioned a few hosts they've hit.
The truth is even if you rented a virtual server in the same data center, your chances of being in the same rack of hardware are pretty slim.
Eg. I can't imagine that if you host with http://www.rackspace.com/ your website would be down if you didn't do anything illegal.
DigitalOne's site is also down http://www.digitalone.com/ so they don't even have a backup server for their own website..
Suppose DigitalOne rents space in a datacenter and has no one on-site (exept for staff from the datacenter). I can imagine that if the FBI enters there "we need servers from IP x.x.x.x and y.y.y.y immediately - that the people from the datacenter just point to the servers from DigitalOne "oh that's in their range"..
Ofcourse that's just speculation if you don't know how it really went down - never the less, I would chose webhosting carefully if your business depends on it:)